Troubleshooting
Cloudflare Error 1010: Banned Based on Your Browser's Signature
Cloudflare error 1010 comes from Browser Integrity Check. What it looks for, what an HTTP client should send, and what only the site owner can change.
By ZeroCaptcha Engineering4 min readPublished Updated
Cloudflare error 1010, “The owner of this website has banned your access based on your browser’s
signature”, means the site’s Browser Integrity Check refused your request. The check is on by
default; it “looks for common HTTP headers abused most commonly by spammers and denies access to
your page”, and “challenges visitors without a user agent or with a non-standard user agent”. For an
HTTP client, the fix is to send a real, consistent User-Agent with ordinary headers. Beyond that,
only the site owner can change it, by turning the check off or skipping it for some paths.
Only automate sites you are allowed to: your own, a client’s, or one whose terms permit it. See responsible captcha automation.
What Browser Integrity Check looks at
Cloudflare’s documentation for error 1010 (checked 1 October 2026) gives the cause as “A website owner blocked your request based on your client’s web browser.” The feature behind it is Browser Integrity Check, and Cloudflare describes it in two sentences:
- It “looks for common HTTP headers abused most commonly by spammers and denies access to your page.”
- It “also challenges visitors without a user agent or with a non-standard user agent such as commonly used by abusive bots, crawlers, or visitors.”
Cloudflare does not publish which headers it looks for, or what counts as a non-standard user agent. So a request can meet the check in two ways: a refusal with error 1010, or a challenge page.
A separate Cloudflare product points the same way. Bot Management’s documentation says “Requests
with a missing or empty User-Agent header are immediately assigned a bot score of 1”, the
score for a request Cloudflare is “quite certain” was automated. That is a different feature from
Browser Integrity Check, with its own rules, but both treat a missing user agent as a strong
signal.
What an HTTP client sends by default
Your HTTP library sends headers of its own unless you set them. Print what it sends before you
guess. In Python with requests:
import requests
print(requests.Session().headers)With requests 2.32.5 on our machine, that printed a User-Agent of python-requests/2.32.5, an
Accept of */*, and two other headers. Whether Cloudflare counts a library’s own user agent as
non-standard isn’t documented, but it is not a browser’s. With curl, curl -v prints each request
header on a line that starts with >:
curl -sv -o /dev/null https://example.com/ 2>&1 | grep '^> 'What to send instead
- A real
User-Agent, never an empty one. Use the user agent of the browser you actually run, or, for an HTTP client, one you send deliberately and can defend. If you drive a real browser with Playwright or Selenium, leave its own user agent alone. - The same user agent for the whole session. Cloudflare lists “a User Agent that changes during
the session” among the causes of failed challenges in WebViews, and describes the
cf_clearancecookie as “securely tied to the specific visitor and device it was issued to.” Pick one and keep it. - Ordinary headers that agree with it. A request that claims to be a browser but sends none of
the headers a browser sends is a mixed signal. Set
AcceptandAccept-Languagethe way a browser would for the page you request, and don’t invent headers. - No forged identities. Don’t claim to be a search engine’s crawler or another verified bot. Cloudflare’s verified bots are ones it has confirmed are “transparent about who it is and what it does”; impersonating one is dishonest, whatever it does to your request.
If you run an honest crawler that names itself in its user agent, the check may still refuse it. In that case the fix is not a disguise but the owner’s exemption, described next.
What the site owner can change
Browser Integrity Check “is enabled by default”. Cloudflare documents three ways for an owner to change it:
- Turn it off for the whole zone under Security > Settings, with the Browser integrity check toggle.
- Skip it for some traffic with a WAF custom rule using the Skip action.
- Turn it on or off for parts of a site with a configuration rule, matching on hostname or URL path.
Cloudflare’s 1010 page sends visitors to the site owner, suggesting a Whois lookup to find a contact, not to Cloudflare. For a partner integration or your own monitor, ask the owner for option 2 or 3 on the paths you use, rather than asking them to turn the check off for everyone.
When the problem is not error 1010
- Error 1020 is a firewall rule the owner wrote, which may match the user agent among other things. See Cloudflare error 1020 and Cloudflare WAF rules explained.
- A “Just a moment…” page is a challenge, not a block, and Browser Integrity Check is one of the features that issue them. A browser can pass it; a plain HTTP client can’t, because it runs no JavaScript. See Cloudflare challenge types and the Cloudflare challenge solver.
A Cloudflare Turnstile token does not change your client’s signature, so a CAPTCHA solver, ZeroCaptcha included, does nothing for error 1010. If your scraper also submits forms protected by Cloudflare Turnstile, Cloudflare Turnstile for web scraping covers that part, and the httpx tutorial shows a Python client that keeps one session and one set of headers.
Sources
- Cloudflare: Error 1010 (checked 1 October 2026)
- Cloudflare: Browser Integrity Check (checked 1 October 2026)
- Cloudflare: Bot detection engines and bot score (checked 1 October 2026)
- Cloudflare: Verified bots (checked 1 October 2026)
- Cloudflare: Challenge solve issues (checked 1 October 2026)
- Cloudflare: Clearance (checked 1 October 2026)
The team that builds and runs the ZeroCaptcha API. Articles are drafted with AI tools, then checked against the API's code and the primary sources each one cites.